Skip to main content

Tools

Ten Factor Governance is not a product: the factors name properties of operable governance. This section covers some tools and standards that already express those properties which have been referenced in the descriptions of the factors.

It is not meant to be an exhaustive list - just a way to help orient the reader whilst understanding the factors.

Each page summarises what the tool is for and which factors it helps and provides a brief jumping-off point for further investigation.

This is not a recommendation - you may find alternatives to these tools which are better suited to your purposes or context, or you may find you don't need a tool at all to achieve your governance objectives: the best software is often no software at all.

  • AWS Config

    AWS service for recording resource configuration, relationships and compliance over time.

  • Backstage

    An open platform for building developer portals with a typed software catalogue, owners and relations.

  • Cedar

    A policy language for authorisation decisions over principals, actions, resources and context.

  • CI/CD

    Continuous integration and continuous delivery—automated pipelines that validate change and promote it through environments.

  • Cloud Asset Inventory

    Google Cloud inventory of assets and relationships across projects and services.

  • Common Cloud Controls

    An open FINOS standard for technology-agnostic cloud security, resiliency and compliance controls with machine-verifiable assessments.

  • CycloneDX

    An OWASP standard for software bills of materials (SBOMs) and related supply-chain inventory formats.

  • DMN

    OMG Decision Model and Notation for executable decision tables and decision requirements diagrams.

  • Flux

    GitOps toolkit for Kubernetes that reconciles desired state and can gate changes with policy.

  • Gatekeeper

    Kubernetes-native policy controller built on OPA, with admission enforcement and audit modes.

  • Gemara

    An activity-centred GRC model with typed, linkable governance artifacts across definition, activity and measurement layers.

  • GitHub CODEOWNERS

    GitHub feature that maps paths to required reviewers so changes have named owners.

  • grc.store

    A registry for publishing, distributing and installing governance artefacts such as control catalogues and related packages.

  • in-toto

    A framework for cryptographically verifying software supply-chain steps via link metadata and layouts.

  • Kubernetes

    Container orchestration platform whose admission controllers intercept API requests before persistence.

  • NIST C-SCRM

    NIST SP 800-161 guidance on cyber supply-chain risk management for acquiring and using ICT products.

  • Open Policy Agent

    A general-purpose policy engine (Rego) that evaluates structured input and returns structured decisions.

  • OpenSSF Scorecard

    Automated security health metrics for open-source projects, produced as machine-readable results.

  • OSCAL

    NIST Open Security Controls Assessment Language for machine-readable controls, profiles and assessment results.

  • ServiceNow CMDB

    An enterprise configuration-management database for IT assets, CIs and relationship maps.

  • SLSA

    Supply-chain Levels for Software Artifacts—provenance requirements that show how an artefact was built.

  • XACML

    OASIS standard for attribute-based access control with request/response evaluation and obligations.